Data Processing Agreement
Contents
1. Definitions
Terms not defined in this Data Processing Agreement ("DPA") have the meaning given to them in the General Data Protection Regulation (EU) 2016/679 ("GDPR") or, where applicable, the UK GDPR and the Data Protection Act 2018.
- "Controller" means the Merchant who installs and configures ConsentCraft on their Shopify store.
- "Processor" means Lucent Labs LLC, publishing entity of ConsentCraft.
- "Subprocessor" means any third party engaged by the Processor to assist in providing the Service.
- "Service" means the ConsentCraft application and all related features, as described in the Terms of Service.
- "Personal Data" has the meaning given in the GDPR.
2. Processing Details
| Subject matter | Operation of the ConsentCraft consent management platform on the Controller's Shopify store |
|---|---|
| Duration | For the term of the Terms of Service between Controller and Processor, plus any applicable retention periods thereafter |
| Nature of processing | Recording, storing, retrieving, and transmitting consent decisions and related audit data |
| Purpose of processing | Enabling the Controller to meet its consent record-keeping obligations under applicable data protection law, and to provide documented evidence of Store Visitor consent decisions |
| Types of personal data | Consent decision (category-level), consent timestamp, consent version identifier, partial IP address (last octet masked), browser type, screen width |
| Categories of data subjects | Store Visitors who interact with the Controller's ConsentCraft consent banner on the Controller's Shopify storefront |
3. Article 28 Obligations
3.1 — Documented Instructions (Art. 28(3)(a))
Processor shall process Personal Data only on documented instructions from the Controller. The Controller's instructions are embodied in the ConsentCraft app configuration set by the Merchant. If Processor is required by Union or Member State law to process Personal Data in a manner not covered by Controller's instructions, Processor will inform Controller before processing, unless prohibited from doing so by law.
If Processor reasonably believes a Controller instruction infringes the GDPR or other applicable data protection law, Processor will promptly inform Controller. Processor is not required to follow instructions that violate applicable law.
3.2 — Confidentiality (Art. 28(3)(b))
Processor ensures that all persons authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3 — Security (Art. 28(3)(c) / Art. 32)
Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- TLS 1.2+ encryption for all Personal Data in transit
- AES-256 encryption for Personal Data at rest
- Multi-tenant data isolation — all Personal Data is stored under shop-scoped partition keys; no cross-tenant access is possible by design
- Role-based access controls limiting access to authorized personnel
- Regular security reviews and vulnerability assessments
- Incident detection and response procedures
3.4 — Subprocessors (Art. 28(3)(d))
Processor shall not engage new Subprocessors without the Controller's general or specific prior authorization. This DPA constitutes the Controller's general authorization for the Subprocessors listed in Section 5. Processor shall give at least 14 days' advance notice before engaging any new Subprocessor by updating the DPA and notifying active Merchants. If the Controller objects to a new Subprocessor on reasonable data protection grounds within the notice period, either party may terminate the Terms of Service.
Where Processor engages Subprocessors, it imposes data protection obligations on those Subprocessors equivalent to those in this DPA. Processor remains liable to Controller for the performance of Subprocessors.
3.5 — Assistance with Data Subject Rights (Art. 28(3)(e))
Processor shall assist Controller in fulfilling its obligations to respond to requests from data subjects exercising their rights under Articles 15 to 22 of the GDPR. Where Processor receives a data subject request that it reasonably believes relates to Personal Data processed on behalf of a Controller, it will forward the request to the relevant Controller within 5 business days without responding to the data subject directly.
3.6 — Assistance with Art. 32–36 Obligations (Art. 28(3)(f))
Processor shall assist Controller in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities), taking into account the nature of processing and the information available to Processor.
3.7 — Deletion or Return (Art. 28(3)(g))
Upon expiry or termination of the Terms of Service, Processor shall, at the choice of the Controller, delete or return all Personal Data processed on the Controller's behalf, and shall delete existing copies, unless Union or Member State law requires storage for a longer period. Deletion will be completed within 30 days of termination unless Controller requests return of data in writing first.
3.8 — Audit Rights (Art. 28(3)(h))
Processor shall make available to Controller all information necessary to demonstrate compliance with this Article, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
Audit conditions:
- Audit requests must be submitted in writing toprivacy@consentcraft.ai
- At least 30 days' advance notice is required
- Audits may be conducted no more than once per calendar year
- Audit costs (including Processor's reasonable time) are borne by Controller
- Audits must not unreasonably disrupt Processor's business operations or compromise other Merchants' data
As an alternative to on-site audit, Processor may satisfy audit obligations by providing relevant security certifications, third-party audit reports, or written attestations from qualified security personnel.
4. Breach Notification
Processor shall notify Controller without undue delay and, where feasible, no later than 72 hours after becoming aware of a personal data breach affecting Personal Data processed under this DPA.
The notification shall, to the extent then known, include:
- A description of the nature of the breach
- The categories and approximate number of data subjects and Personal Data records affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach, including mitigation steps
Where information is not available at the time of initial notification, Processor shall provide it as soon as reasonably practicable in supplementary notifications. Notification to Controller does not constitute an admission of fault or liability.
Breach notifications must be sent to the Merchant email address on file. The Controller is responsible for its own notifications to supervisory authorities and affected data subjects as required by applicable law.
5. Authorized Subprocessors
The Controller provides general authorization for the following Subprocessors as of the effective date of this DPA:
| Subprocessor | Role | Location | Safeguard |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure (Lambda, DynamoDB, S3, CloudFront) | United States | SCCs + AWS Customer Agreement DPA |
| Amazon Simple Email Service | Transactional email delivery | United States | SCCs + AWS Customer Agreement DPA |
| Shopify Inc. | App platform (billing, OAuth, app distribution) | Canada / United States | SCCs + Shopify DPA |
| Bunny Way d.o.o. (Bunny CDN) | Static asset delivery (JavaScript, CSS bundles) | EU + global edge network | Bunny CDN Data Processing Agreement |
DPA links and copies of relevant SCCs are available upon request atprivacy@consentcraft.ai.
6. International Data Transfers
Transfers of Personal Data from the European Economic Area (EEA) or United Kingdom to third countries (including the United States) are safeguarded by Standard Contractual Clauses pursuant to European Commission Implementing Decision 2021/914 (Controller-to-Processor module) for transfers to AWS and Shopify. Copies of the applicable SCCs are available upon written request.
Article 27 representative: As of the effective date of this DPA, Processor has not appointed a formal representative in the EU or UK under Article 27 GDPR. Processor is actively evaluating representative services. Controllers are encouraged to seek independent legal advice regarding their own Art. 27 exposure where relevant.
7. Liability
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service, except as otherwise required by mandatory applicable law.
Notwithstanding anything in the Terms of Service, nothing in this DPA or the Terms of Service limits or excludes either party's liability under GDPR Article 82 to data subjects who have suffered damage as a result of an infringement of the GDPR. Where Processor has caused damage to a data subject as a direct result of Processor's breach of its obligations as a data processor under Chapter IV of the GDPR, the aggregate cap in the Terms of Service does not apply to that liability.
If either party pays compensation to a data subject for damage caused by an infringement for which both parties are jointly responsible, that party may seek contribution from the other party to the extent the other party is responsible for the same damage, in accordance with Article 82(5) GDPR.
8. Governing Law
This DPA is governed by the laws of the State of California without prejudice to mandatory data protection law provisions applicable in the jurisdiction of the Controller. For EU/EEA Controllers, the mandatory requirements of the GDPR take precedence over any conflicting provision in this DPA.
For questions regarding this DPA or to request a countersigned copy, contact:
Lucent Labs LLC
Email:privacy@consentcraft.ai